Re: Securing Fedora Core 4

From: Glynn Clements (glynn_at_gclements.plus.com)
Date: 09/25/05

  • Next message: Andrea Pasquinucci: "Re: Securing Fedora Core 4"
    Date: Sun, 25 Sep 2005 01:44:16 +0100
    To: "AragonX" <aragonx@dcsnow.com>
    
    

    AragonX wrote:

    > Well, the offices that I will be setting up are rather small and I can't
    > convince them to separate the services to multiple machines.
    >
    > So basically, the servers will have to do everything. Email, web,
    > firewall, gateway, file & print. Those are the tasks it will have to
    > perform.

    > Email and web are the services that will be available to the Internet.

    The public web server should definitely be a separate box, especially
    if it has any kind of CGI or scripting capability (i.e. mod_cgi,
    mod_perl, mod_php etc), and it shouldn't be given any trust (i.e. any
    firewall rules or access lists which distinguish between "internal"
    and "external" systems should treat the web server as external).

    Rule #1 of running a web server: assume that it is going to get
    compromised occasionally. Obviously, you try to prevent that, but
    don't assume that you will be entirely successful.

    -- 
    Glynn Clements <glynn@gclements.plus.com>
    

  • Next message: Andrea Pasquinucci: "Re: Securing Fedora Core 4"

    Relevant Pages

    • Re: 2 differnet domains, 1 SQL server under 1 firewall and DSL connection...help
      ... there is 1 firewall out to the net ... there is a SQL server w/ accounting data on it where BOTH ... there's no reason that two separate logical networks can't ...
      (microsoft.public.win2000.networking)
    • Re: ipfilter or ip xyz filtering security question
      ... > Do you think it is necessary to enforce security on a freebsd server and use ... already uses other forms of security. ... any more secure just because it's behind the firewall. ... There are many ways to write your firewall rules. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Non-Portal content not being returned in search results?
      ... On a separate note, I did manage to solve the WSS search problem. ... we had a single-server SPS 2003 solution running on SQL ... Server 2005 Express. ... that same server still hosts the SPS 2003 ...
      (microsoft.public.sharepoint.portalserver)
    • Re: too many illegal connection attempts through ssh
      ... > attempts to login to my server from a suspicious ... enough to stop these bulk attacks on my server. ... a combination of firewall & alternative sshd port. ... I suppose you're familiar enough with firewall rules. ...
      (freebsd-questions)
    • Re: Organization split - comments welcome
      ... Totally separate network; totally separate part of the city!! ... Or even being on the "same network". ... using Windows SBS 2003 Standard Edition. ... So, an additional server was purchased running Windows 2003 Server, ...
      (microsoft.public.windows.server.active_directory)